you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 3 months ago

That's the difference between a security researcher who gives, and does not give a shit about peoples security.

The grace period is to protect people by giving the company time to send out patches. At 1 month, they publish the exploit to shame the company and get the cred either way.

  • source
  • parent